Add Severity Levels and response time
2 unresolved threads
2 unresolved threads
Compare changes
+ 22
− 12
@@ -64,29 +64,39 @@ Please refer to the CVE Process for details.
@@ -64,29 +64,39 @@ Please refer to the CVE Process for details.
"Best effort" is slippery slope [1] [2] We should use something like "commercially reasonable effort"
[1] https://definitions.uslegal.com/b/best-efforts/#:~:text=Best%20efforts%20is%20a%20contractual,ability%20to%20meet%20the%20goal. [2] https://www.lexology.com/library/detail.aspx?g=6a4c20dc-594d-4756-b710-7a2dc213e8c0
3 working days for critical issue maybe too long from the users point of view. And way to long from the business point of view.
CC @dricci783
Do we have any calculations that back any of the numbers here? Can we even offer a 3 day response time on critical bugs?